fake-whatsapp-star-blizzard

How Russian hackers went after NGOs’ WhatsApp accounts

Share:

Star Blizzard, a threat actor tied to the Russian Federal Security Service (FSB), was spotted attempting to compromise targets’ WhatsApp accounts through a clever phishing campaign.

The campaign

The campaign started with a spear-phishing email that was made to look like it was sent by a US government official.

“We have established a private WhatsApp group to facilitate discussions regarding the latest non-govermental initiatives aimed at supporting Ukraine. This platform will also serve as a means to coordinate the distribution of government-allocated funds for this purpose,” the email says. “You can join us using this QR code below.”

The QR code doesn’t work, though, pushing the victim to reply to say as much. Then, the attackers send a second email, with a shortened link instead of a QR code.

The link leads to a spoofed WhatsApp webpage asking them to go through several steps to join the group.

The spoofed WhatsApp page, with the QR code obscured (Source: Microsoft Threat Intelligence)

“However, this QR code is actually used by WhatsApp to connect an account to a linked device and/or the WhatsApp Web portal,” Microsoft’s threat analysts explained.

“This means that if the target follows the instructions on this page, the threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web.”

About Star Blizzard

The campaign seems to have been aimed at non-governmental organization (NGO) employees and, according to Microsoft, it started in mid-November and ended by the end of the month.

Nevertheless, it shows how Star Blizzard changes its tactics, techniques, and procedures (TTPs) and persists in achieving its goals.

“Star Blizzard’s targets are most commonly related to government or diplomacy (both incumbent and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of assistance to Ukraine related to the war with Russia,” the threat analysts noted.

They’ve also been known to target Russian citizens residing in the US, UK citizens, and computer networks belonging to NATO.

In late 2024, the Microsoft and the US Justice Department seized 100+ domains used the group, ans set the stage for further disruption any new infrastructure through an existing court proceeding.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:16 am, Mar 12, 2025
weather icon 7°C
L: 6° | H: 8°
broken clouds
Humidity: 72 %
Pressure: 1004 mb
Wind: 8 mph NW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:21 am
Sunset: 5:59 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0.2 mm 20% 9 mph 85 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 7°°C 0.89 mm 89% 9 mph 96 % 1007 mb 0.22 mm/h
Fri Mar 14 9:00 pm
weather icon
1° | 8°°C 0.2 mm 20% 8 mph 89 % 1015 mb 0 mm/h
Sat Mar 15 9:00 pm
weather icon
2° | 8°°C 0.2 mm 20% 14 mph 82 % 1025 mb 0 mm/h
Sun Mar 16 9:00 pm
weather icon
4° | 9°°C 0 mm 0% 12 mph 71 % 1027 mb 0 mm/h
Today 12:00 pm
weather icon
5° | 7°°C 0 mm 0% 6 mph 72 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 9 mph 65 % 1003 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 7 mph 67 % 1002 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0.2 mm 20% 9 mph 85 % 1003 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 81 % 1003 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 2°°C 0 mm 0% 7 mph 86 % 1002 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 2°°C 0.2 mm 20% 6 mph 96 % 1002 mb 0.2 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0.2 mm 20% 9 mph 76 % 1003 mb 0.22 mm/h
Name Price24H (%)
Bitcoin(BTC)
€75,582.40
1.21%
Ethereum(ETH)
€1,744.32
-0.47%
Tether(USDT)
€0.92
0.01%
XRP(XRP)
€2.01
2.29%
Solana(SOL)
€114.40
0.77%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.153078
3.88%
Shiba Inu(SHIB)
€0.000011
4.31%
Pepe(PEPE)
€0.000005
8.84%
Scroll to Top